Despite not being a financial markets-specific set of mandates, GDPR nonetheless pertains to capital markets-facing companies and the reams of personally identifiable information data points and personal datasets used to power their business and trading franchises on a front-to-back basis. Specifically, this report examines the implementation and compliance implications of the regulation from the perspective of the investment banking divisions of EU-based banks, regardless of their size or tiering.
The objective of GreySpark’s research around GDPR is to narrate a step-by-step explanation of how a bank could utilise best practices when using process and policy to drive implementation, compliance and – ultimately – regulatory change initiatives.